GrayShift has long been known worldwide for its GrayKey device that can unlock iPhones, but few people really understand how it works. Recently, leaked user manuals surfaced online, giving everyone a clearer look at what this device can do and how it operates.
Previously, reports said the iPhone or iPad unlocking device uses brute-force attacks to guess passcodes. While not the most ideal method, GrayKey has helped law enforcement agencies gain access to locked iPhones multiple times.

The leaked manual appears to come from the San Diego Police Department, written to guide officers on how to use the device, and was found by Motherboard. The document instructs users to “confirm whether law enforcement has permission to search the Apple device”.
The manual explains different conditions for GrayKey to connect: when the device is off (called BFU, before First Unlock), when the phone is powered on (After First Unlock or AFU), if the screen is broken, or if the battery is low.

To unlock the device, the manual says: “GrayKey installs a piece of code (called an agent) when the device’s battery is between 2% and 3%.” This code is used to brute-force the passcode, but the iPhone must stay powered until the password is found.

When running GrayKey, users can choose what type of data to extract from the iPhone. This can include metadata from inaccessible files or “immediate extraction once the SE is unlocked“, SE likely stands for Secure Enclave, the part of iOS that stores sensitive info like passwords and encryption keys.
Part of the manual also details how GrayKey brute-forces passcodes with characters. While many iPhone users use numeric-only passcodes, character-based passwords include letters, making brute-force attacks harder. However, if the password uses readable words, cracking becomes easier since GrayKey has a long list of human-readable words.
This list is in a file called “Crackstation-human-only.txt” containing about 1.5 billion words and passwords. GrayKey can use other wordlists too, but only one list is active at a time.

Once the “agent” code is installed, the iPhone switches to Airplane mode and can disconnect from GrayKey.
Another feature called HideUI lets GrayKey install a second piece of code that secretly records the user’s passcode in case law enforcement needs to return the iPhone to the suspect.
GrayKey and similar companies are in a constant cat-and-mouse game with Apple, trying to break into locked iPhones. Every time Apple updates its OS or security layers, GrayShift and others upgrade their methods to bypass the new protections.
Source: AppleInsider